Malware

Downloader.Win32.Agent.minr removal guide

Malware Removal

The Downloader.Win32.Agent.minr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.minr virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

downloader.downerapi.com
dxz.51xiazai.cn
source.downerapi.com
img.downerapi.com

How to determine Downloader.Win32.Agent.minr?


File Info:

crc32: C5116847
md5: 7642b468a36e7439dc1ce9dace5ab29b
name: ____________bitspirit_036415339.exe
sha1: 2a1b7f9544e9ea266c501b7b2c5057fb1101b5f7
sha256: abca6d7b8adc4f225eef361b4cf4503b9825729884ff83a5ae21670950bdef3a
sha512: 7f5db45eff12a88c682ed679602320f55c124890577981d975996e1f3a81c3a3615bf636e6f52d8878824b4460874401cd91406d04c823a5585097dcc9d15ae7
ssdeep: 24576:BPm854PVMJm1RrRoXO2KRgC6RbZxBv1K2BfU/BiNndJ:BPm8OimTrRoZKuNRFPv/tU/BiNndJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.minr also known as:

MicroWorld-eScanGen:Variant.Adware.Downloader.211
FireEyeGeneric.mg.7642b468a36e7439
McAfeeArtemis!7642B468A36E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Adware.Downloader.211
K7GWRiskware ( 0055e5601 )
K7AntiVirusRiskware ( 0055e5601 )
TrendMicroTROJ_FRS.0NA103EF20
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/RiskWare.Downer.B
TrendMicro-HouseCallTROJ_FRS.0NA103EF20
Paloaltogeneric.ml
GDataGen:Variant.Adware.Downloader.211
Kasperskynot-a-virus:Downloader.Win32.Agent.minr
AlibabaDownloader:Win32/Downer.8e0b8be3
RisingAdware.Downloader!1.BD64 (CLOUD)
Ad-AwareGen:Variant.Adware.Downloader.211
SophosGeneric PUA CK (PUA)
ComodoApplicUnwnt@#3myesa3rzsnjq
F-SecureHeuristic.HEUR/AGEN.1126112
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
EmsisoftApplication.Downloader (A)
APEXMalicious
CyrenW32/Adware.IZZQ-0076
MaxSecureTrojan.Malware.75393012.susgen
AviraHEUR/AGEN.1126112
Antiy-AVLRiskWare[Downloader]/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Adware.Downloader.211
AhnLab-V3PUP/Win32.Generic.C3478818
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.minr
MicrosoftPUA:Win32/Downer
ALYacGen:Variant.Adware.Downloader.211
MAXmalware (ai score=98)
VBA32Downloader.Agent
MalwarebytesPUP.Optional.FastDownloader
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Agent
WebrootW32.Adware.Gen
AVGFileRepMalware [PUP]
PandaTrj/Genetic.gen

How to remove Downloader.Win32.Agent.minr?

Downloader.Win32.Agent.minr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment